ContiºÏ×÷ͬ°éÒòÐÄ»³²»Âú¹«¿ª¸ÃÍÅ»ïC2µØÖ·µÈÐÅÏ¢ £»£»£» £»£»£» £»ESETÅû¶14¸ö¶Ô×¼IIS Web·þÎñÆ÷µÄ¶ñÒâÈí¼þ¼Ò×å

°ä²¼¹¦·ò 2021-08-06

1.Òâ´óÀûÄÜÔ´¹«Ë¾ERGÔâµ½ÀÕË÷Èí¼þLockBit 2.0¹¥»÷


1.jpg


Òâ´óÀûÄÜÔ´¹«Ë¾ERG³ÆÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£ ¡£¡£¡£ERGÊÇÒâ´óÀûµ±ÏȵķçµçÔËÓªÉÌ£¬£¬£¬£¬£¬£¬Ò²ÊÇÅ·ÖÞÊг¡Ê®´ó½ÉÏÔËÓªÉÌÖ®Ò»¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬ÓÉÓÚ·¢ÏÖ¹¥»÷ºóѸËÙ×°ÖÃÁËÄÚ²¿°²È«·¨Ê½£¬£¬£¬£¬£¬£¬Òò¶øÆäÐÅÏ¢ºÍͨѶ¼¼Êõ(ICT)»ù´¡ÉèÊ©¡°Ö»²úÉúÁ˼¸´ÎÇá΢µÄÖжϡ°£¬£¬£¬£¬£¬£¬ÇÒĿǰÔÚ»º½âÕâЩÖжÏ¡£¡£¡£ ¡£¡£¡£La Repubblica±¨Â·³Æ£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÊÇÓÉÀÕË÷ÍÅ»ïLockBit 2.0×éÖ¯µÄ¡£¡£¡£ ¡£¡£¡£ÔÚ²»¾Ãǰ£¬£¬£¬£¬£¬£¬Òâ´óÀûÀ­Æë°Â´óÇøÒ²Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ¼Ö¸õØÓòµÄITϵͳ̱»¾¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/energy-group-erg-reports-minor-disruptions-after-ransomware-attack/    


2.ESETÅû¶14¸ö¶Ô×¼IIS Web·þÎñÆ÷µÄ¶ñÒâÈí¼þ¼Ò×å


2.jpg


ESET×êÑÐÈËÔ±ÔÚBlack Hat USA°²È«»áÒéÉϰ䲼ÁË14¸ö¶Ô×¼IIS Web·þÎñÆ÷µÄ¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬£¬ÆäÖÐÓÐ10¸öÊÇмͼµÄ¡£¡£¡£ ¡£¡£¡£¸Ã×êÑÐ×ܹ²ÍøÂçÁË80¶à¸ö¶ñÒâÈí¼þÑù±¾£¬£¬£¬£¬£¬£¬²¢½«ËüÃÇ·ÖΪÁË14¸ö¼Ò×壬£¬£¬£¬£¬£¬ÆäÖдó²¿ÃÅÊÇÔÚ2018ÄêÖÁ2021ÄêÆÚ¼ä³õ´Î¼ì²âµ½µÄ£¬£¬£¬£¬£¬£¬²¢ÇÒĿǰÈÔÔÚ»ý¼«¿ª·¢ÖС£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâÈí¼þ¶¼ÊÇ·þÎñÆ÷¶Ë¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ËüÃÇÖØÒªÓÐÁ½¸öÖ°ÄÜ£º²é¿´²¢À¹½ØÓë·þÎñÆ÷µÄËùÓÐͨѶ£¬£¬£¬£¬£¬£¬ÒÔ¼°Ó°ÏìÒªÇóµÄ´¦Ö÷½Ê½¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/several-malware-families-targeting-iis.html


3.×êÑÐÈËÔ±Åû¶Cobalt StrikeÖлؾø·þÎñ·ì϶µÄϸ½Ú


3.jpg


SentinelLabs×êÑÐÈËÔ±Åû¶ÁËCobalt StrikeÖлؾø·þÎñ·ì϶µÄϸ½Ú¡£¡£¡£ ¡£¡£¡£Cobalt StrikeÊǺϷ¨µÄÉøÈë²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬£¬ÖØÒª×÷Ϊºì¶ÓµÄ¹¥»÷¿ò¼Ü£¬£¬£¬£¬£¬£¬Í¬Ê±Ò²±»ºÚ¿ÍÓÃÓÚ¹¥»÷»î¶¯¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2021-36798£¨²¢³ÆÎªHotcobalt£©£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÔÚÖ¸±ê·þÎñÆ÷ÉÏ×¢²á¼Ùbeacon£¬£¬£¬£¬£¬£¬¶øºóÏò·þÎñÆ÷·¢ËÍÐéα¹¤×÷À´ºÄ¾¡¿ÉÓÃÄÚ´æ¶øÊ¹·þÎñÆ÷±ÀÀ££¬£¬£¬£¬£¬£¬½ø¶øµ¼ÖÂÖ¸±êÎÞ·¨ÓëC2ͨѶ£¬£¬£¬£¬£¬£¬×ÌÈźì¶Ó£¨»òºÚ¿Í£©µÄ²Ù×÷¡£¡£¡£ ¡£¡£¡£HelpSystems¹«Ë¾ÔÚCobalt Strike 4.4Öн¨¸´ÁË·ì϶¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cobalt-strike-bugs-allow-takedown-of-attackers-servers/


4.¹È¸è°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Chromeä¯ÀÀÆ÷ÖÐ10¸ö·ì϶


4.jpg


¹È¸è°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÁËChromeä¯ÀÀÆ÷ÖеÄ10¸ö·ì϶¡£¡£¡£ ¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪɳÏäÌÓÒÝ·ì϶£¨CVE-2021-30590£©£¬£¬£¬£¬£¬£¬¿ÉÔÚChromeµÄɳÏäÖ®±íʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬»¹ÓÐTab GroupsÖеÄÔ½½çдÈë·ì϶£¨CVE-2021-30592£©ºÍTab StripsÖеÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-30593£©£¬£¬£¬£¬£¬£¬ÈôÊǹ¥»÷ÕßÄÜÔÚÔ½½ç¶ÁÈ¡²úÉú֮ǰÊʵ±µÄÉèÖÃÄڴ棬£¬£¬£¬£¬£¬¾ÍÓпÉÄÜÀûÓÃÕâÁ½¸ö·ìÏ¶ÈÆ¹ýɳÏä¡£¡£¡£ ¡£¡£¡£Õâ´Î»¹½¨¸´ÁËCVE-2021-30591ºÍCVE-2021-30594µÈ·ì϶¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-patches-several-chrome-flaws-can-be-exploited-malicious-extensions


5.ContiºÏ×÷ͬ°éÒòÐÄ»³²»Âú¹«¿ª¸ÃÍÅ»ïC2µØÖ·µÈÐÅÏ¢


5.jpg


ContiµÄºÏ×÷ͬ°éÒò¶ÔÀûÒæ·ÖÅä²»¹«¶øÐÄ»³²»Âú£¬£¬£¬£¬£¬£¬¹«¿ªÁ˸ÃÍÅ»ïµÄC2µØÖ·µÈ»úÃÜÐÅÏ¢¡£¡£¡£ ¡£¡£¡£Conti×÷ΪRaaS£¬£¬£¬£¬£¬£¬ÆäÖ÷ÌâÍŶÓÖÎÀí¶ñÒâÈí¼þºÍTorÕ¾µã£¬£¬£¬£¬£¬£¬¶øºóÕÐļºÏ×÷ͬ°éÖ´ÐÐÍøÂç·ì϶ºÍ¼ÓÃÜÉ豸¡£¡£¡£ ¡£¡£¡£Í¨³£Ö÷ÌâÍŶÓ׬ȡÊê½ðµÄ20-30%£¬£¬£¬£¬£¬£¬¶øÆäËüÈË׬ȡÔü×Ò²¿ÃÅ¡£¡£¡£ ¡£¡£¡£Õâ´Î¹«¿ªÁËCobalt Strike C2·þÎñÆ÷µÄIPµØÖ·ºÍÒ»¸ö113 MBµÄµµ°¸£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ºÚ¿Í¹¤¾ß¡¢¶íÎÄÊֲᡢÅàѵ×ÊÁϺÍÔ®ÊÖÎĵµ¡£¡£¡£ ¡£¡£¡£¹«¿ªÕ߳ƣ¬£¬£¬£¬£¬£¬ËûÃÇÖ®ËùÒÔ°ä²¼ÕâЩ×ÊÁÏ£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚËûÔÚ¹¥»÷ÖÐÖ»»ñµÃÁË1500ÃÀÔªµÄ±¨´ð£¬£¬£¬£¬£¬£¬¶øÆäËû³ÉÔ±Ôò׬ȡÁËÊý°ÙÍòÃÀÔª¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±½¨ÒéÿÓ×ÎÒ¶¼×èÖ¹ÕâЩIPµØÖ·£¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÀ´×Ô¸Ã×éÖ¯µÄ¹¥»÷¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/angry-conti-ransomware-affiliate-leaks-gangs-attack-playbook/


6.Group IB°ä²¼TaskMasters¹¥»÷¶íÂÞ˹µÄ·ÖÎö»ã±¨


6.jpg


Group IB°ä²¼ÁËÓйØTaskMasters¶Ô¶íÂÞ˹µÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¸Ã»ã±¨ÖØÒªÃèÊöÁËÔÚ2020ÄêÕë¶Ô¶íÂÞ˹Áª¹úÐÐÕþµ±¾ÖµÄ¹¥»÷Öмì²âµ½µÄWebdav-O¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÁËÕë¶Ôx86ºÍx64ϵͳµÄÁ½¸ö°æ±¾µÄwebdev-o£¬£¬£¬£¬£¬£¬ÆäÖÐx64°æ±¾±»ÓÃÓÚ¹¥»÷¶íÂÞ˹£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÖÁÉÙ´Ó2018ÄêÆðÍ·¾Í´æÔÚÁË¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ÓÉÓÚWebdav-OÖÐÓÐÒ»×éºÅÁîÀàËÆÓÚBlueTraveller£¨±ðÃû RemShell£©£¬£¬£¬£¬£¬£¬Òò¶ø×êÑÐÈËԱȷ¶¨Õâ´Î¹¥»÷»î¶¯ÓëºÚ¿Í×éÖ¯TaskMastersÓйØÁª¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.group-ib.com/task